PT-2023-17137 · Otcms · Otcms

Fzh1613

·

Published

2023-03-25

·

Updated

2024-05-17

·

CVE-2023-1635

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions OTCMS version 6.72
Description A vulnerability was found in the function AutoRun of the file apiRun.php. The manipulation of the argument mode leads to cross-site scripting. The attack can be launched remotely.
Recommendations For OTCMS version 6.72, consider disabling the AutoRun function of the apiRun.php file until a patch is available. Restrict access to the apiRun.php file to minimize the risk of exploitation. Avoid using the mode argument in the affected function until the issue is resolved.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2023-1635

Affected Products

Otcms